Skip to content

Rate-Topics can be used to DoS individual (public) topics #1048

Closed
@binwiederhier

Description

@binwiederhier

The attack is this:

  • Subscribe to mytopic with the rate topics header including "mytopic"
  • Everyone who subscribes to that topic will count towards that one IPs 250 message limit
  • After 250 messages, done

I will remove the rate-topics header entirely as a result, and just enable visitor rate limiting for "up*" topics.

Metadata

Metadata

Assignees

No one assigned

    Labels

    🔒 securitySecurity related ticket🪲 bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions